HomeSecurityGitea RCE: Critical vulnerability exploited by hackers

Gitea RCE: Critical vulnerability exploited by hackers

The critical RCE vulnerability CVE-2026-60004 in Gitea is being actively exploited, according to an urgent advisory issued by the US Cybersecurity and Infrastructure Security Agency ( CISA ). The vulnerability, with a CVSS score of 9.8 , allows an attacker with simple write permissions to a repository to execute arbitrary shell commands as the Gitea OS user . The situation is particularly concerning as confirmed exploits have already been documented online, with attackers deploying cryptominer payloads on vulnerable systems.

Gitea RCE vulnerability CVE-2026-60004 cryptominer exploit

CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) on August 25, 2026, confirming that the threat is not theoretical but real. The vulnerability affects all Gitea from 1.17 to 1.27.0, while the fix was released with version 1.27.1 in late July 2026. Security researcher Shai Rod (aka NightRang3r) is credited with discovering and reporting the issue to the Gitea development team.

Gitea is a popular, lightweight self-hosted Git, widely used by developers, software development teams, and organizations that want to keep their code off of large cloud platforms. It is precisely this widespread use in self-hosted environments — often without strict security monitoring — that makes the vulnerability particularly dangerous for thousands of installations worldwide.

See also: CVE-2026-60236: Critical RCE in Oracle Coherence (CVSS 9.8) – what to do now

How the Gitea vulnerability CVE-2026-60004 works

The technical issue is in the way Gitea handles applying patches via the POST endpoint /api/v1/repos/{owner}/{repo}/diffpatch. According to Gitea's official announcement, "the diffpatch endpoint can be misused to install and execute a Git hook from content controlled by the repository." The dangerous interaction occurs between the diffpatch stream, a temporary bare clone, and Git's conflict resolution behavior, which can write a malicious hook to the repository's hooks directory.

The most worrying aspect of the vulnerability is that it doesn’t require administrator privileges. All it takes is an account with write permissions to a repository. And here’s the crucial detail: Gitea allows new users to freely register by default. This means that an external attacker could create an account, create a repository, gain the necessary write permissions, and then activate the exploit — without needing any pre-existing credentials. CISA describes the vulnerability as a “code injection vulnerability that allows an attacker with write permissions to a repository to send a malicious patch to the diffpatch API endpoint, install an executable Git hook, and execute shell commands as the Gitea service account.”

Gitea RCE: Critical vulnerability exploited by hackers

Settings that make a Gitea installation particularly vulnerable include: DISABLE_REGISTRATION = false (free user registration), REGISTER_EMAIL_CONFIRM = false (no email confirmation), ENABLE_OPENID_SIGNUP = true (registration via OpenID), and REQUIRE_SIGNIN_VIEW = false (no login required to view pages or use APIs). This combination of default settings creates an ideal environment for exploitation.

Real-life incident: Gitea RCE for cryptominer development

A real-life case of RCE exploitation was revealed in an analysis published by developer Andrey (known as @Causelof) on the Russian blogging platform Habr. His Gitea installation was targeted by an unknown threat actor who used CVE-2026-60004 to deploy a dropper with cryptocurrency miner. The incident was revealed when hosting provider HOSTKEY sent a notification that the virtual server was using more than 70% of its processing power for an extended period of time, violating its terms of service.

See also: CVE-2026-56163: Critical EoP in Azure Kubernetes Service (AKS) – Mitigated by Microsoft

The dropper script executed through the vulnerability followed a series of steps before deploying the final payload: it cleared the LD_PRELOAD and LD_LIBRARY_PATH, looked for processes with high CPU usage, attempted to terminate competing processes, retrieved the payload based on the system architecture, downloaded and executed it, and finally deleted the file after execution. The exact nature of the final payload remains unknown, as the user did not analyze its contents, however the sharp increase in CPU usage is consistent with a cryptojacking targeting vulnerable Gitea installations.

Protection from the Gitea vulnerability: Immediate steps

The most critical action for any organization using Gitea is to immediately upgrade to version 1.27.1 or later, which contains the official fix for CVE-2026-60004. In addition, administrators should review user registration settings and disable free registration if not necessary, while enabling email confirmation. Disabling ENABLE_OPENID_SIGNUP and enabling REQUIRE_SIGNIN_VIEW can also significantly reduce the attack surface.

Security teams should review logs for unusual activity on the diffpatch and suspicious filesystem changes related to hooks. If signs of exploitation are found, it is recommended to assume the system has been compromised and immediately rotate the credentials and tokens used by the Gitea service account. For organizations subject to federal or regulatory requirements, CISA has set a specific remediation deadline through the KEV catalog.

See also: Meshtastic: Critical GitHub Actions flaw with pull_request_target allows supply chain compromise (CVE-2026-44359)

Article image: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - illustration 1

Additionally, it is recommended to conduct a complete inventory of all Gitea installations in the organization, with particular emphasis on those accessible from the internet. Reviewing repository permissions and removing unnecessary write permissions are also important risk mitigation measures.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Overall, the CVE-2026-60004 vulnerability is a prime example of how default security settings can turn a technical weakness into a critical threat. The ease of exploitation — which does not require pre-existing credentials — combined with the widespread use of Gitea in self-hosted environments makes immediate response imperative. According to The Hacker News, CISA did not disclose details about who is behind the attacks, but the inclusion in the KEV catalog is a clear signal that the exploit is real and active.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS